{"id":"MGASA-2026-0379","summary":"Updated exiv2 package fixes security vulnerabilities","details":"Heap out-of-bounds write in RemoteIo when reading from a malicious\nremote server (WebReady/Curl builds). (CVE-2026-68546)\nHeap out-of-bounds read in RemoteIo when reading block-aligned remote\nCRW files. (CVE-2026-68547)\nOut of bounds read in CrwMap::decodeBasic. (CVE-2026-49275)\n","modified":"2026-09-07T19:12:29.073041155Z","published":"2026-09-07T18:46:11Z","upstream":["CVE-2026-49275","CVE-2026-68546","CVE-2026-68547"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0379.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36221"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/08/30/1"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp"},{"type":"ADVISORY","url":"https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w"}],"affected":[{"package":{"name":"exiv2","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/exiv2?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.28.9-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0379.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}